1,219 questions with Active Directory Federation Services tags

Sort by: Updated
1 answer

Configuring multiple UPN for ADFS SSO support with Office 365?

I've deployed ADFS 4.0 using Windows Server 2016 and OnPremise AD is synched using Azure AD Connect for the Hybrid configuration. Since our AD structure is Single Forest Single Domain AD and I can see the information like below from the Azure…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,355 questions
asked 2020-07-17T11:53:36.613+00:00
EnterpriseArchitect 5,036 Reputation points
commented 2020-07-21T07:25:02.52+00:00
AmanpreetSingh-MSFT 56,486 Reputation points
2 answers One of the answers was accepted by the question author.

ADFS understanding needed

Hi All, I have been asked quite a few questions about our infrastructure and in particular ADFS (Active Directory Federation Services). I have no idea as I don't have anything to do with Federated Services. I don't even know if it is set up in our…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-07-20T08:28:23.263+00:00
czql5v 221 Reputation points
commented 2020-07-20T14:07:46.13+00:00
czql5v 221 Reputation points
3 answers

Federate from ADFS to Third Party Identity Provider

Have noticed that it is possible to federate from Azure AD to third party identity providers like Okta, Ping Identity via the Azure Portal (the customer does not want to use Azure AD) Is it possible to do the same via ADFS. Where when a client calls…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-07-19T23:08:00.41+00:00
Artha Wijendra 131 Reputation points
answered 2020-07-20T11:15:04.87+00:00
Andy David 701 Reputation points
1 answer One of the answers was accepted by the question author.

ADFS & HRD sign in page

Hello, We are facing an issue when applying HRD on lab & prod environement. We have 2 directories for authentication. We use ADFS installed on Windows Server 2019. We use OrganizationalSuffix (Set-AdfsLocalClaimsProviderTrust -TargetName…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-07-09T09:36:25.813+00:00
Jean-Luc Ch 176 Reputation points
accepted 2020-07-17T10:03:48.117+00:00
Jean-Luc Ch 176 Reputation points
0 answers

ADFS 2.0 to 2016 migration - Service won't start after configuration import

Hello, I'm working on the migration of my ADFS 2.0 server (running 2008 R2) to ADFS 4.0 (on WS2016). All went fine during the ADFS 2016 farm installation, but as soon as I imported my 2.0 configuration, the ADFS service stopped and won't start. I'm…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-07-07T15:48:55.623+00:00
Fouziya LAHJIOUJ 1 Reputation point
commented 2020-07-15T15:11:13.883+00:00
Fouziya LAHJIOUJ 1 Reputation point
1 answer

ADFS - configuration to support Multi Forest environment.

Hello Friends, One our client is going to implement Cloud based SAP solution. Currently client is having 3 different Active Directory Forests and there is a trust between. The question is here, can we install one ADFS server and add and configure…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-07-13T10:31:44.607+00:00
Abul Fazal 26 Reputation points
answered 2020-07-13T16:31:21.443+00:00
s ganesamoorthy 161 Reputation points
1 answer

Steps / Procedures for configuring Office 365 with OnPremise ADFS 4.0 (2016) to allow SSO passwordless company-wide.

As I'm using Hybrid Office 365 and Exchange 2013 environment and the OnPremise AD is synced to Azure AD using Azure AD Connect. version 1.4.18.0 I have successfully configured and deployed multiple ADFS 4.0 (2016) in my corporate WAN environment. …

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,355 questions
asked 2020-07-09T07:29:57.247+00:00
EnterpriseArchitect 5,036 Reputation points
commented 2020-07-13T07:12:14.95+00:00
AmanpreetSingh-MSFT 56,486 Reputation points
1 answer

Steps and procedures when changing service account for ADFS and Azure AD Connect?

Hi Everyone, May I know what's the least amount of privilege for the Group Managed Service Accounts required for the ADFS v4.0 and Azure AD Connect ? Because at the moment the environment I'm managing is using Domain Administrator account, which…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,355 questions
asked 2020-07-10T02:36:28.717+00:00
EnterpriseArchitect 5,036 Reputation points
commented 2020-07-10T06:39:08.483+00:00
T. Kujala 8,706 Reputation points
2 answers One of the answers was accepted by the question author.

Upgrade the ADFS schema and Decommission the old 2012 R2 ADFS server

Hi All, I need some help in the steps and procedure for the existing ADFS v 3.0 (2012 R2) Migration to ADFS 4.0 (2016)? As at the moment, I have one ADFS farm called FS.domain.com: 1x old Windows Server 2012 R2 - PROD-ADFS01-VM (running as the…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-07-08T14:05:12.077+00:00
EnterpriseArchitect 5,036 Reputation points
commented 2020-07-10T01:50:46.14+00:00
JamesTran-MSFT 36,531 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Steps and procedure when upgrading ADFS to Windows Server 2016 with no outage?

Hi All, I wonder if anyone here can suggest the steps and procedure to perform an upgrade of current OnPremise Windows Server 2012 R2 ADFS server into Windows Server 2016. I have found this article for the upgrade:…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,355 questions
asked 2020-06-17T06:49:04.837+00:00
EnterpriseArchitect 5,036 Reputation points
commented 2020-07-09T07:21:13.14+00:00
EnterpriseArchitect 5,036 Reputation points
0 answers

ADFS SingleLogoutService

Hello, We are having some issues with the SingleLogoutService. Where is the SingleLogoutService updated? This location points to a "page cannot be found" so we are trying to configure it. <SingleLogoutService…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-06-30T11:48:37.967+00:00
Dre 1 Reputation point
commented 2020-07-07T23:42:15.7+00:00
Pierre Audonnet - MSFT 10,171 Reputation points Microsoft Employee
2 answers

Bypass a HRD page using user login only and continue authentication on external provider. ADFS 2016\2019

I want to bypass HRD page on ADFS. Some of my RP already has parameter like login_hint for openID Connect and RedirectToIdentityProvider for WS Federation. But one RP should direct users to different external IPs depending on their login. We don't use…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-04-05T02:49:02.847+00:00
Sergey A 1 Reputation point
commented 2020-07-07T09:13:49.263+00:00
Sergey E 1 Reputation point
1 answer

ADFS 3.0 2012 R2 - I need help identifying my farm federation servers and if safe to remove old ones.

Hi I inherited our ADFS infrastructure with little documentation, and I am trying to identify how everything i working together. I have a document of the layout, so I know server named and purposes, but I immediately became confused, as the layout…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-07-06T14:49:26.99+00:00
Bill Crum 56 Reputation points
answered 2020-07-06T21:55:35.817+00:00
Pierre Audonnet - MSFT 10,171 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

E-mail claim not available from my external authentication method in AD FS 2016

I'm trying to plug a custom mfa provider to AD FS 2016, and while everything could work, I still have an issue when trying to specify which identity claim should be passed to my code. If in my dll I specify an Identity Claim with upn, it works: …

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-06-19T11:55:14.657+00:00
Cho7 21 Reputation points
commented 2020-07-01T14:22:39.05+00:00
Cho7 21 Reputation points
0 answers

AD FS - Single Identifier with Multiple Endpoints - Index Selection in iDP Initiated Sign-On?

We have a requirement from a service provider to provide SSO for two separate parts of their web service - a user endpoint and an admin endpoint. We have a single RP identifier that applies to both so we have configured two endpoints with the respective…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-06-30T14:48:40.98+00:00
Iain Jones 1 Reputation point
commented 2020-07-01T13:30:17.41+00:00
Iain Jones 1 Reputation point
1 answer

Convert my federated identity to standard

I setup my tenant with a Lab for federation and now the lab server no longer exists. I need to change my tenant back to standard. I tried to follow this article. https://gallery.technet.microsoft.com/office/Convert-MsolDomain-To-ced5a502 Thanks

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,355 questions
asked 2020-06-29T17:23:40.727+00:00
Thor Fayad 1 Reputation point
answered 2020-06-30T16:22:42.723+00:00
Shashi Shailaj 7,581 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

ADFS 2012R2 Claims that map from LDAP to SAML2 output not always clear

I'm trying to create a claim issuance policy. One of the mappings has to be the user SID. When I use the Get-ADUser powershell cmdlet I can see the User SID property is "SID", but when I try to find that in the list of pre-defined LDAP menu…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-06-26T23:15:41.013+00:00
Mike Murphy 41 Reputation points
accepted 2020-06-29T15:07:21.193+00:00
Mike Murphy 41 Reputation points
3 answers

ADFS SSL Renewal

So I am very new to AD FS and have been dropped in it. I have an SSL Cert that is going to expire in 7 days time. The production System has 2 AD server with FS on and 2 Proxy Server. I have created a test plaform that mimics the production as best I can…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-06-26T12:20:49.203+00:00
Chris Farmer 36 Reputation points
commented 2020-06-29T14:53:44.133+00:00
Chris Farmer 36 Reputation points
1 answer One of the answers was accepted by the question author.

Features and packages in Windows server 2019

With the help of the dism command and the /Get-Features switch I got a list of features and packages that are enabled or disabled in my installation. Is there any link that explains what these features do? (e.g. feature name: Tpm-PSH-Cmdlets). I…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-06-29T05:54:18.017+00:00
accepted 2020-06-29T08:29:14.82+00:00
0 answers

ADFS and MFA in Microsoft Browsers

Hi I'm after some help or suggestions as to what could be causing some odd behaviour in ADFS. A little background first. We have 2 WAP severs sitting in front of 2 ADFS servers which cal on 2 third party MFA severs, in our case Securenvoy. I'm using…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
asked 2020-06-23T12:47:05.08+00:00
Barry Pain 1 Reputation point
commented 2020-06-27T16:46:42.717+00:00
Pierre Audonnet - MSFT 10,171 Reputation points Microsoft Employee